30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

2.3.3.2 dc3dd<br />

Dc3dd is another enhanced version <strong>of</strong> existing DD program. It is developed and<br />

maintained by the US Department <strong>of</strong> Defense Cyber Crime Centre. Most <strong>of</strong> the<br />

features were inspired by dcfldd and modified <strong>for</strong> dc3dd (Kornblum & Medico, 2009).<br />

The major improvements over the original DD and dcfldd programs are the<br />

per<strong>for</strong>mance improvements, sector error recovery, detailed logging, error sector<br />

reporting and log file appending (Kornblum & Medico, 2009).<br />

2.3.3.3 Helix 3 Pro<br />

Helix 3 is compatible in multiple plat<strong>for</strong>ms and has several open source <strong>for</strong>ensic<br />

applications to assist digital <strong>for</strong>ensic investigations. Many open source applications are<br />

built in a bootable Live CD. Helix 3 Pro has a simple to use interface and it can boot to<br />

any x86 system in a <strong>for</strong>ensically sound manner. Helix 3 Pro supports DD and Encase<br />

version 4, 5 and 6 imaging <strong>for</strong>mats. Volatile data collection option is also available in<br />

Helix 3 Pro. Helix 3 Pro also compiles report with detailed data collection results.<br />

2.3.3.4 Automated Image and Restore (AIR)<br />

AIR is a GUI tool <strong>for</strong> DD/dc3dd with specific design <strong>for</strong> creating <strong>for</strong>ensics images in a<br />

simple way (Gibson, 2010). It supports dd/dc3dd image <strong>for</strong>mats and the block size is<br />

customisable. AIR detects wide range <strong>of</strong> devices such as IDE, SATA, SCSI and tape<br />

drives. It provides many choices <strong>of</strong> Hash algorithms such as MD5, SHA1/256/384/512<br />

and Gzip/bzip2 compressions. AIR can split images into multiple segment parts <strong>for</strong><br />

better storage option and image over a data network via encrypted or unencrypted<br />

connection. It can also wipe devices into specific patterns.<br />

2.3.3.5 Aimage (Part <strong>of</strong> AFF Library)<br />

Aimage is part <strong>of</strong> tool libraries <strong>of</strong> Advanced <strong>Forensic</strong> Format (AFF) which is open<br />

source <strong>for</strong>ensic s<strong>of</strong>tware. It is capable <strong>of</strong> creating files in dd, AFF, AFD or AFM<br />

<strong>for</strong>mats and supports compression and uncompression. The AFF is a smart, tested<br />

system <strong>for</strong> creating and acquiring <strong>for</strong>ensic disk images (Simson, Malan, Dubec,<br />

Stevens, & Pham, 2006). Aimage can recover a device with bad sectors or blocks and<br />

has similar recovery mechanism as dd_rescue. Byers & Shahmehri (2009) stated that<br />

32

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!